Re: Book.

2002-10-18 Thread Michael Lucas
3.3, as you did between 3.1 and 3.2? That'll tell me how many pages I can spend on it... if the user-visible interface is still flopping around, I have to trim the page count I'm planning for it. ==ml -- Michael Lucas [EMAIL PROTECTED], [EMAIL PROTECTED] ht

Re: Book.

2002-10-18 Thread Michael Lucas
On Fri, Oct 18, 2002 at 01:56:30PM +0200, Henning Brauer wrote: > On Fri, Oct 18, 2002 at 07:43:56AM -0400, Michael Lucas wrote: > > So, Dan, are you planning to rework the whole pf tool suite for 3.3, > > as you did between 3.1 and 3.2? That'll tell me how many pages I can &

Re: Call for comments on using OpenBSD 3.2 as a VPN Server (road warrior)

2002-11-14 Thread Michael Lucas
ur cooperation. > > SONNENSCHEIN NATH & ROSENTHAL > Visit us on the web at http://www.sonnenschein.com > --- > -- Michael Lucas [EMAIL PROTECTED], [EMAIL PROTECTED] http://www.oreillynet.com/pub/q/Big_Scary_Daemons Absolute BSD: http://www.AbsoluteBSD.com/

Re: Pf rules stuff with MS PDC & BDC

2002-11-26 Thread Michael Lucas
be a rule set problem, I've > done something wrong, could suggest what I might be able to do to get > this working. > -- Michael Lucas [EMAIL PROTECTED], [EMAIL PROTECTED] http://www.oreillynet.com/pub/q/Big_Scary_Daemons Absolute BSD: http://www.AbsoluteBSD.com/

return-icmp and a particular code

2002-12-09 Thread Michael Lucas
numbers on the line. Judging from Google, nobody else is trying to specify message 3 code 9 or such. How do these need to be formatted? Thanks! ==ml -- Michael Lucas [EMAIL PROTECTED], [EMAIL PROTECTED] http://www.oreillynet.com/pub/q/Big_Scary_Daemons

Re: TCP Flags question

2002-12-11 Thread Michael Lucas
g the OS would save me time and energy. My question is, are the flags above reasonable if concealing your OS is your goal? ==ml -- Michael Lucas [EMAIL PROTECTED], [EMAIL PROTECTED] http://www.oreillynet.com/pub/q/Big_Scary_Daemons Absolute BSD: http://www.AbsoluteBSD.com/

Re: TCP Flags question

2002-12-11 Thread Michael Lucas
On Wed, Dec 11, 2002 at 03:07:20PM +0100, Saad Kadhi wrote: > On Wed, Dec 11, 2002 at 08:08:55AM -0500, Michael Lucas wrote: > > On Wed, Dec 11, 2002 at 02:02:28PM +0100, Henning Brauer wrote: > > > oh wow, a real advantage. > > > if someone wants to know I'm runni

reloading only scrub rules?

2002-12-15 Thread Michael Lucas
Hello, pfctl(8) has options to reload only options, only NAT rules, only filtering rules, and so on, but no option to reload only the scrub rules. Can you reload scrub rules without reloading the entire rules file? Thanks, ==ml -- Michael Lucas [EMAIL PROTECTED], [EMAIL PROTECTED

Re: Very Annoying problem... blocks everything...

2002-12-16 Thread Michael Lucas
their network. > do a ping from the firewall, and you get: > > ping: sendto: No route to host > ping: wrote 192.168.3.250 64 chars, ret=-1 > > > Anyone have any ideas? > > -- Michael Lucas [EMAIL PROTECTED], [EMAIL PROTECTED] http://www.oreillynet.com/pub/q/Big_Scary_Daemons Absolute BSD: http://www.AbsoluteBSD.com/

Re: PF extension for address/network tables

2002-12-20 Thread Michael Lucas
e: stability and correctness before new cool stuff. Don't get me wrong: new cool stuff is good. Making existing cool stuff work correctly is better. Designing current interfaces with an eye towards later reuse by planned new cool stuff is also better. But my pager never going off is best of

Re: PF extension for address/network tables

2002-12-20 Thread Michael Lucas
On Fri, Dec 20, 2002 at 07:57:52PM +0100, Daniel Hartmeier wrote: > On Fri, Dec 20, 2002 at 01:46:27PM -0500, Michael Lucas wrote: > > > > I'm questing wether we still should bring new shit in. The number of bugs we > > > found recently is scary, and the new shit need

altq, ssh, and tos

2002-12-22 Thread Michael Lucas
States: 0 ] openbsdtest/etc; I'm not passing any packets over my SSH rules, but I am passing packets over the "pass all" rule. Am I misunderstanding ToS? Is the documentation wrong, and does interactive SSH actually use some other ToS? Do I obviously need more sleep, be

Re: altq, ssh, and tos

2002-12-23 Thread Michael Lucas
On Mon, Dec 23, 2002 at 01:39:04PM +0100, Henning Brauer wrote: > On Sun, Dec 22, 2002 at 11:24:57PM -0500, Michael Lucas wrote: > > When I add a ToS field to that same rule, it appears that that rule is > > not being processed; instead, it uses the default "pass all" rule

pfctl: DIOCADDRULE: Device busy

2002-12-24 Thread Michael Lucas
Hello, Updated once in the morning yesterday, and once in the afternoon after getting this error. # pfctl -R -f pf.conf pfctl: DIOCADDRULE: Device busy # I can reload the whole rules file, just not the rules section alone. Any suggestions? ==ml -- Michael Lucas [EMAIL PROTECTED

interpreting pfctl -s info

2002-12-24 Thread Michael Lucas
ot;normalize" is the number of packets normalized by scrub. That leaves me wondering what "match" and "memory" mean. Any help would be appreciated. Merry Christmas, all! ==ml -- Michael Lucas [EMAIL PROTECTED], [EMAIL PROTECTED] http://www.oreillynet.com/pub/q/Big_Scary_Daemons Absolute BSD: http://www.AbsoluteBSD.com/

panic in authpf

2002-12-26 Thread Michael Lucas
port 0x2f8/8 irq 3: ns16550a, 16 byte fifo fdc0 at isa0 port 0x3f0/6 irq 6 drq 2 fd0 at fdc0 drive 0: 1.44MB 80 cyl, 2 head, 18 sec biomask 4a40 netmask 4a60 ttymask 5ae2 pctr: user-level cycle counter enabled mtrr: Pentium Pro MTRR support dkcsum: sd0 had no matching BIOS disk dkcsum: sd1 had no matc

Re: panics when using reply-to

2002-12-28 Thread Michael Lucas
hat hosts > them. Todd Miller might get to the machine tomorrow, and hopefully the > lists will be back up soon. You might have to resend some posts, if they > got lost. -- Michael Lucas [EMAIL PROTECTED], [EMAIL PROTECTED] http://www.oreillynet.com/pub/q/Big_Sc

viewing just authpf rules or authpf states?

2002-12-28 Thread Michael Lucas
created for them." Any suggestions? Or should I just wade through "pfctl -a authpf -s authpf"? -- Michael Lucas [EMAIL PROTECTED], [EMAIL PROTECTED] http://www.oreillynet.com/pub/q/Big_Scary_Daemons Absolute BSD: http://www.AbsoluteBSD.com/

Request for review: PF book section

2002-12-28 Thread Michael Lucas
see as the most popular parts. I cannot post a public URL, as that would be "prior publication" and invalidate my contract with my publisher. If you would be willing to do this review, however, please contact me and I will send you the chapter. I would need any completed feedback by

Re: Request for review: PF book section

2002-12-28 Thread Michael Lucas
at, Dec 28, 2002 at 03:49:55PM -0500, Michael Lucas wrote: > Hello, > > As some on this list know, I'm writing a book on OpenBSD. > > Most of the book I can test myself -- I can sit and build ports and do > installs all day long, after all. The sections on PF are a little &